Bitcoin punched through 80,000 dollars for the first time since May, riding a 25% weekly rally after the U.S. Treasury signaled it could tap its 950 billion dollar cash pile for bond buybacks. ETF inflows extended to a seventh straight day, adding 337 million dollars Monday. Strategy raised 2 billion by selling MSTR shares but bought zero Bitcoin, parking 1.59 billion in a new cash pool instead. Anthropic opened up its Mythos 5 model to more cybersecurity defenders and launched a 35 million dollar open source fund. Binance let AI agents start trading crypto on behalf of users. And Coldcard shipped an emergency firmware update after a randomness flaw drained 130 million in Bitcoin. Let's dig in.
So Bitcoin is back above 80,000 dollars, up roughly 25% in seven days, and the catalyst is not what most people expected. It wasn't an ETF headline or a corporate treasury announcement. It was the U.S. Treasury floating the idea of using its Treasury General Account, roughly a trillion dollars sitting at the Fed, to expand bond buybacks and stabilize long-term government debt. That's a fancy way of saying more liquidity, and risk assets responded fast. The rally has real structural support underneath it. Futures open interest actually collapsed during the move, which is the signature of a short squeeze followed by spot buying rather than leveraged froth. Funding rates stayed subdued. Spot Bitcoin ETFs pulled in 337 million dollars on August 24th, extending an unbroken streak to six days and 2.26 billion dollars. Year-to-date net outflows have narrowed to about 2.57 billion, so we're close to erasing the damage from earlier in the year. But not everyone is buying it. Bitget CEO Gracy Chen said she doesn't think the rally is sustainable and is waiting to buy more around 50,000 dollars later this year or early next. Bitcoin also just got rejected at 81,000, capped by its 50-week moving average. That level matters. A weekly close above the 50-week EMA would be the first bear-market trend line reclaim since late 2025. Traders are already positioning for more upside. Options desks are seeing a 2.9 million dollar bet on a rapid jump above 82,000. But demand for downside protection remains firm, which tells you the market isn't fully convinced. The billionaire Stanley Druckenmiller weighed in on the Treasury buyback plan itself, calling it a dangerous intervention that removes the market's ability to police government borrowing. Whether you love it or hate it, that's the fuel behind this rally.
Strategy did something interesting this week, and it's worth understanding what it signals. The company raised about 2 billion dollars by selling 18.26 million MSTR shares between August 17th and 23rd. In previous cycles, that money would have gone straight into Bitcoin. This time, none of it did. Holdings stayed flat at 840,447 BTC, bought at an average cost of 75,385 dollars per coin. Instead, Strategy did three things. It spent 136 million dollars buying back its STRC preferred shares. It added 300 million to its USD Reserve, bringing that pool to 5.1 billion. And it created an entirely new liquidity bucket called USD Cash, seeded with 1.59 billion dollars. Total cash across pools is now 6.69 billion. Management says the new cash pool gives flexibility to fund Bitcoin purchases, preferred dividends, debt payments, or securities repurchases, whichever makes sense given market conditions. Analysts note the cash reserves now cover about 2.8 years of expected dividends. That's a defensive posture from a company that used to buy every dip aggressively. Meanwhile, Metaplanet is going the opposite direction, expanding. It's investing 2,100 Bitcoin, worth about 132 million dollars, plus 2.5 million in cash into Super League Enterprise. The combined entity will be renamed Superplanet and become a Metaplanet subsidiary listed on both Nasdaq and the Tokyo Stock Exchange. Metaplanet will own about 95.7% of it. Metaplanet already holds 43,000 BTC, and this deal creates a dual-listed U.S.-Japan Bitcoin treasury platform. Strive also stayed in accumulation mode, buying 1,110 BTC for 81.5 million dollars at an average price of 73,409. Its holdings now top 21,000 Bitcoin, and shares jumped 11%. So the treasury companies are diverging. Some are hoarding dry powder, some are still stacking. That divergence itself is a signal about where the smart money thinks we are in this cycle.
Anthropic made a significant move this week that changes how frontier AI gets used in cybersecurity. It's expanding access to Claude Mythos 5, its highest-capability model, but only for defenders, and only through very tightly controlled interfaces. Here's the setup. Mythos 5 has been restricted for a while because of its dual-use potential. It's the model that could theoretically help someone attack systems just as well as defend them. So instead of opening up raw model access, Anthropic built a product layer called Claude Security. It's in public beta for Claude Enterprise customers. You connect your GitHub codebase, it runs scans on Mythos 5, and you get back structured findings. CWE category, confidence rating, severity, and suggested patches. Crucially, you never touch the model directly. The output is defensive recommendations, not open-ended reasoning that could be repurposed for offense. Findings run through an adversarial verification pass to cut false positives, and any patch requires human approval before it touches your code. Outputs export to Slack, Jira, CSV, or Markdown. Pricing is standard token usage, 10 dollars per million input tokens and 50 dollars per million output tokens, which is not cheap for large codebases. Anthropic also launched the Defender Advantage Fund, 35 million dollars in Claude credits earmarked for open source maintainers to patch vulnerabilities and automate scans. That matters because a lot of the vulnerabilities Mythos 5 finds live inside universally used open source libraries. And they're expanding the Cyber Verification Program to let vetted defenders access reduced-safeguard versions of Opus and Sonnet, with Mythos access coming through Project Glasswing in partnership with U.S. government agencies for critical infrastructure. The interesting tension here is philosophical. Anthropic is arguing that the safest way to deploy dangerous AI is through purpose-built interfaces that return specific outputs, not through general model access. It's a different model from OpenAI's more open approach. And given the Hugging Face incident this month, where open-weight Chinese models used for defense turned out to have their own guardrail problems, the debate about open versus safeguarded frontier AI is very much live.
If you hold your own Bitcoin in a hardware wallet, this next one is required listening. Coldcard, one of the most respected air-gapped hardware wallets, just shipped an emergency firmware update after attackers drained about 130 million dollars in Bitcoin. Galaxy Research puts the confirmed losses at 1,789 BTC across 221 victim reports, though 87% of the stolen coins haven't moved yet. The root cause is a firmware flaw dating back to 2021. A build error caused seed generation to use a software random number generator called Yasmarang instead of the device's hardware RNG. That dropped entropy in some cases to just 40 bits, which is guessable with modern compute. Attackers started draining wallets in July. The first known incident saw 594 BTC, about 38 million dollars, siphoned off in 25 minutes. The fix is firmware 5.6.1 for the Mk4 and Mk5, and 1.5.1Q for the Q model. The big change: you can no longer generate a seed automatically. You have to supply your own randomness. At least 65 timed key presses, or 50 dice rolls, or 128 coin flips. Coldcard also swapped the RNG to a SHA-256 Hash_DRBG seeded from both secure elements, added boot-time verification that entropy actually comes from hardware, and now checks staged PSBTs immediately before signing so a compromised computer can't swap a transaction after review. If your seed was generated on affected firmware, updating alone doesn't fix it. You need to generate a new wallet with proper entropy and move your coins. Passphrases don't save you either. Coldcard isn't alone in getting caught. BitBox pushed out its own Dixence update after AI-assisted internal audits found two severe firmware bugs, including a bootloader flaw that could have allowed malicious firmware via a phishing attack. And Ledger patched an Ethereum app bug that could display one transaction while signing another. Three major hardware wallet vendors, three serious security disclosures, all in the same month. The takeaway isn't that hardware wallets are broken. They're still the best available option for self-custody. But the assumption that a device is trustworthy the day you buy it and forever after is wrong. Firmware updates matter. Entropy matters. And if you generated a Coldcard seed between 2021 and this month, stop what you're doing and check the advisory.
If a single 2021 build error can cost 130 million dollars in Bitcoin five years later, the real lesson is that self-custody is not a one-time setup. It's a maintenance discipline. Check your firmware.